ISO 27001 to HIPAA: control mapping & evidence reuse
10 of 13 control domains map directly. See exactly where ISO 27001 and HIPAA overlap, which evidence carries over, and which engagement to run first.
How ISO 27001 and HIPAA relate
Companies that sell software or services into healthcare usually end up needing both ISO 27001 and HIPAA. ISO 27001 is an internationally recognized certification of an information security management system (ISMS) that buyers everywhere understand, while HIPAA is United States law that applies whenever you create, receive, maintain, or transmit protected health information (PHI) as a covered entity or business associate. If your customers are hospitals, payers, or digital-health vendors, they will often ask for both an ISO certificate and evidence that you meet the HIPAA Security Rule.
Structurally the two frameworks look different but rhyme. ISO 27001:2022 pairs mandatory ISMS clauses 4 through 10 with Annex A, which holds 93 controls grouped into four themes: organizational (A.5), people (A.6), physical (A.7), and technological (A.8). The HIPAA Security Rule lives in 45 CFR Part 164, Subpart C, and organizes requirements into administrative safeguards (§164.308), physical safeguards (§164.310), technical safeguards (§164.312), and policies and documentation (§164.316). Both are risk-based: ISO drives everything from clause 6.1.2 risk assessment, and HIPAA anchors its program on the §164.308(a)(1) risk analysis.
This crosswalk is practical guidance from AuditNex, not an official government or standards-body mapping. It shows, domain by domain, where an ISO 27001 control has a genuine HIPAA counterpart and where the two frameworks simply do not line up. Remember that HIPAA has no certification and no mandated audit; the HHS Office for Civil Rights enforces it, and any third-party HIPAA attestation is voluntary.
Domain-by-domain mapping
Each row pairs the closest ISO 27001 and HIPAA requirements for one control domain. This is practical audit-planning guidance, not an official crosswalk published by the standards bodies.
Across 13 control domains, 10 map directly between ISO 27001 and HIPAA, 3 map partially, and 0 have no equivalent on one side. Counts are computed live from the mapping table below.
| Control domain | ISO 27001 reference | HIPAA reference | Match & notes |
|---|---|---|---|
| Governance & risk assessment | ISMS clauses 5-6, 6.1.2 and 8.2; A.5.1 | §164.308(a)(1) incl. risk analysis (a)(1)(ii)(A) | Direct match Both make a documented, ongoing risk assessment the foundation of the program. ISO adds a formal ISMS governance layer of leadership, objectives, and management review that HIPAA does not spell out. |
| Policies & documentation | A.5.1; clause 7.5 documented information | §164.316 | Direct match Both require written, maintained security policies and records. HIPAA mandates six-year retention of documentation, while ISO focuses on version-controlled documented information tied to the ISMS. |
| Access control & identity | A.5.15-A.5.18 | §164.308(a)(4); §164.312(a) and (d) | Direct match Both require access to be granted by role, users uniquely identified, and authentication enforced. ISO A.5.15-A.5.18 map closely to HIPAA information-access management plus the §164.312 access-control and authentication standards. |
| Change management | A.8.32 | §164.308(a)(1) (implied via risk analysis) | Partial ISO A.8.32 requires formal change control. HIPAA has no explicit change-management standard, so any change discipline is inferred from its ongoing risk-analysis and evaluation duties, making the overlap partial. |
| Data protection & encryption | A.8.24 | §164.312(a)(2)(iv), (c) and (e) | Direct match Both call for encryption of data at rest and in transit and for integrity protection. HIPAA treats encryption as addressable, meaning implement or document why not, whereas ISO A.8.24 requires a defined cryptography policy. |
| Logging & monitoring | A.8.15-A.8.16 | §164.312(b); §164.308(a)(1)(ii)(D) | Direct match Both require recording and reviewing system activity. HIPAA audit controls plus information-system-activity review align with ISO logging and monitoring, though ISO is more prescriptive about clock synchronization and log protection. |
| Incident response | A.5.24-A.5.28 | §164.308(a)(6) | Direct match Both require documented procedures to detect, respond to, and learn from security incidents. HIPAA layers on breach-notification obligations outside the Security Rule that ISO does not address. |
| Vendor & third-party risk | A.5.19-A.5.23 | §164.308(b); §164.314(a) | Direct match Both require contractual and security oversight of third parties handling data. HIPAA centers on business associate agreements, while ISO expects broader supplier risk assessment and monitoring across the relationship. |
| Business continuity & availability | A.5.29-A.5.30 | §164.308(a)(7) | Direct match Both require continuity and recovery planning, including data backup, disaster recovery, and testing. HIPAA's contingency-plan standard maps closely to ISO continuity and ICT-readiness controls. |
| Personnel security & training | A.6.1-A.6.6 (incl. A.6.3 awareness) | §164.308(a)(3) and (a)(5) | Direct match Both require screening, defined responsibilities, and ongoing security awareness training. HIPAA (a)(5) training maps to ISO A.6.3, and workforce clearance and termination align with A.6.1-A.6.6. |
| Asset & configuration management | A.5.9-A.5.14; A.8.9 | §164.310(d) | Partial ISO requires an asset inventory, information classification, and configuration management. HIPAA addresses only device and media controls and has no explicit configuration-management or classification standard, so overlap is partial. |
| Physical & environmental security | A.7.1-A.7.4 | §164.310(a)-(c) | Direct match Both require controlling physical access to facilities and protecting workstations. HIPAA facility-access and workstation controls align with ISO physical-security controls, though ISO covers environmental threats in more depth. |
| Vulnerability & patch management | A.8.8 | §164.308(a)(1) and (a)(5)(ii)(B) | Partial ISO A.8.8 requires managing technical vulnerabilities. HIPAA has no explicit vulnerability-scanning or patching standard; the expectation flows indirectly from risk analysis and the malicious-software-protection provision, so overlap is partial. |
Which should you do first?
For most teams the ISO 27001 engagement is the better anchor to run first. It produces a certifiable ISMS with a defined scope, a risk-treatment process, and a Statement of Applicability, all assessed by an accredited certification body on a three-year cycle. Because that program already covers the large majority of HIPAA's administrative, physical, and technical safeguards, meeting HIPAA afterward becomes mostly a gap-and-mapping exercise rather than a fresh build.
The market reality is that HIPAA has no certificate to earn, so companies rarely run a standalone HIPAA audit. Many pair HIPAA with SOC 2 to give healthcare buyers a report they can rely on, and treat HIPAA as an overlay of PHI-specific obligations on top of a broader security program. If you are already an ISO 27001 shop moving into healthcare, layer the HIPAA-specific requirements onto your existing ISMS: business associate agreements, breach notification procedures, and PHI-scoped access and disclosure controls.
If you must stage both from scratch, define one combined control environment, run the ISO 27001 certification audit, and then perform a HIPAA Security Rule gap assessment against the same controls. Document the addressable-versus-required decisions HIPAA calls for, and record where PHI is stored and transmitted so the scope of each program is clear and defensible.
Evidence you can reuse
A large share of evidence carries directly from an ISO 27001 program into a HIPAA review. The documented risk assessment, information security policies, access-provisioning and access-review records, incident-response procedures, security awareness training logs, business continuity and disaster-recovery test results, supplier and vendor reviews, and physical access records all satisfy the analogous HIPAA safeguards with little rework.
What does not carry over is the HIPAA-specific and PHI-specific material. Business associate agreements and their §164.314 requirements, the Breach Notification Rule procedures, HIPAA's addressable-versus-required implementation determinations, and PHI data-flow scoping have no ISO equivalent and must be produced separately. Going the other direction, the ISO Statement of Applicability, the certification-body audit evidence, and the ISO certificate itself are not something HIPAA recognizes, because HIPAA has no certification.
Find auditors for each framework
No directory firm is currently confirmed for both ISO 27001 and HIPAA — browse each ranking separately, or submit one request covering both and let firms respond.
Budget both engagements
AuditNex publishes first-party and industry rate data for each framework so you can plan the combined spend before talking to anyone.
ISO 27001 cost data › · HIPAA cost data › · All compliance audit costs ›
One request, both frameworks
Tell us your scope once — get transparent quotes from vetted firms that can run ISO 27001 and HIPAA together.
Get matched →Related crosswalks
Sources: ISO/IEC 27001:2022, Information security management systems - Requirements (clauses 4-10); ISO/IEC 27001:2022 Annex A (93 controls across themes A.5-A.8); HIPAA Security Rule, 45 CFR Part 164, Subpart C (§164.302 through §164.318); U.S. Department of Health and Human Services (HHS), Office for Civil Rights guidance. Mapping maintained by the AuditNex research team; last reviewed July 26, 2026. This crosswalk is practical guidance for planning combined audits — it is not an official mapping published by AICPA, ISO, HHS, DoD, or the FedRAMP PMO, and your auditor makes the final scoping call.